Technical Forum
Ask questions. Discover Answers.
cancel
Showing results for 
Search instead for 
Did you mean: 

About IPsec Interface

young19918
Altocumulus
Altocumulus

Hello,

When I was building IPsec Interface  I found that I could not select the option I wanted...

young19918_0-1684393714173.png
But I've obviously put this option up ....

young19918_1-1684394021967.png

Why can't I select it in " Tunnels : Profiles : IPsec Interface" ?

Any help is appreciate....

7 REPLIES 7

Paulius
MVP
MVP

@young19918 I would imagine that you have to change the order and place the traffic selector that you created before the default one. Typically what happens is selectors are used from top to bottom on most devices so this could be what is causing the F5 to not allow you to select the other one in your options.

@Paulius ,

Thanks for your reply.

After I changed the order ,I still can't choose...

young19918_0-1684485600778.png

young19918_1-1684485633638.png

 

@young19918 Can you provide the rest of the associated configuration for this IPsec VPN? From my understanding the following is all that should be configured, assuming you have done all the prerequisits such as a self-IP.

1. Create a forwarding virtual server for IPsec. This should listen on destination 0.0.0.0/0, all ports, all protocols, and all vlans and tunnels
2. Create an IKE peer
3. Create an IPsec policy
4. Create an IPsec traffic selector. Make sure this one is above the default.

The following article might help you in this configuration.

https://techdocs.f5.com/kb/en-us/products/big-ip_ltm/manuals/product/bigip-tmos-tunnels-ipsec-13-0-0...

Hi @Paulius ,

Yes, I have already configured.

1.  Forwarding_IP

young19918_3-1684913728015.png

2. IKE peer

young19918_2-1684913707062.png

3. Ipsec policy

young19918_1-1684913686412.png

4. IPsec traffic selector

young19918_0-1684913658280.png

 

 

@young19918 And nothing is showing up in any of your VPN related logs on the F5?

Hi @Paulius ,

Yes...

@young19918 Anything in the logs on the other end?